Scope
Article 2
1. This Regulation applies to cybersecurity aspects of cross-border electricity flows in the activities of the following entities, if they are identified as high-impact or critical-impact entities in accordance with Article 24: (a) electricity undertakings as defined in Article 2(57) of Directive (EU) 2019/944; (b) nominated electricity market operators (‘NEMOs’) as defined in Article 2(8) of Regulation (EU) 2019/943; (c) organised market places or ‘organised markets’ as defined in Article 2(4) of Commission Implementing Regulation (EU) No 1348/2014 ( 14 ) that arrange transactions on products relevant to cross-border electricity flows; (d) critical ICT service providers as referred to in Article 3, point (9) of this Regulation; (e) the ENTSO for Electricity established pursuant to Article 28 of Regulation (EU) 2019/943; (f) the EU DSO entity established pursuant to Article 52 of Regulation (EU) 2019/943; (g) balancing responsible parties as defined in Article 2, point (14) of Regulation (EU) 2019/943; (h) operators of recharging points as defined in Annex I to Directive (EU) 2022/2555; (i) regional coordination centres (‘RCCs’) as established pursuant to Article 35 of Regulation (EU) 2019/943; (j) managed security service providers (‘MSSP’) as defined in Article 6(40) of Directive (EU) 2022/2555; (k) any other entity or third party to whom responsibilities have been delegated or assigned pursuant to this Regulation. 2. The following authorities are, as part of their current mandates, responsible to perform tasks assigned in this Regulation: (a) the European Union Agency for the Cooperation of Energy Regulators (‘ACER’) established by Regulation (EU) 2019/942 of the European Parliament and of the Council ( 15 ) ; (b) national competent authorities responsible for carrying out the tasks assigned to them under this Regulation and designated by Member States pursuant to Article 4, or ‘competent authority’; (c) national regulatory authorities (‘NRAs’) designated by each Member State pursuant to Article 57(1) of Directive (EU) 2019/944; (d) competent authorities for risk preparedness (‘RP-NCAs’) established pursuant to Article 3 of Regulation (EU) 2019/941; (e) computer security incident response teams (‘CSIRTs’) as designated or established pursuant to Article 10 of Directive (EU) 2022/2555; (f) competent authorities responsible for cybersecurity (‘CS-NCAs’) as designated or established pursuant to Article 8 of Directive (EU) 2022/2555; (g) the European Union Agency for Cybersecurity established pursuant to Regulation (EU) 2019/881; (h) any other authorities or third party to whom responsibilities have been delegated or assigned pursuant to Article 4(3). 3. This Regulation shall also apply to all entities who are not established in the Union but who deliver services to entities in the Union, provided they have been identified as high or critical-impact entities by the competent authorities in accordance with Article 24(2). 4. This Regulation is without prejudice to the Member States’ responsibility for safeguarding national security and their power to safeguard other essential State functions, including ensuring the territorial integrity of the State and maintaining law and order. 5. This Regulation is without prejudice to the Member States’ responsibility for safeguarding national security with respect to activities in the production of electricity from nuclear powers plants, including activities within the nuclear value chain, in accordance with the Treaties. 6. Entities, the competent authorities, the single points of contact at entity level and the CSIRTs shall process personal data to the extent necessary for the purposes of this Regulation and in accordance with Regulation (EU) 2016/679, in particular such processing shall rely on Article 6 thereof.